Wind River Support Network

HomeDefectsSCP7-248
Fixed

SCP7-248 : Security Advisory - linux - CVE-2016-0728

Created: Jan 20, 2016    Updated: May 29, 2018
Resolved Date: Jan 29, 2016
Previous ID: LIN7-5496
Found In Version: 7.0.0.11
Fix Version: 7.0.0.13
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Kernel

Description

http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728 says:

Perception Point Research team has identified a 0-day local privilege escalation vulnerability in the Linux kernel. While the vulnerability has existed since 2012, our team discovered the vulnerability only recently, disclosed the details to the Kernel security team, and later developed a proof-of-concept exploit. As of the date of disclosure, this vulnerability has implications for approximately tens of millions of Linux PCs and servers, and 66 percent of all Android devices (phones/tablets). While neither us nor the Kernel security team have observed any exploit targeting this vulnerability in the wild, we recommend that security teams examine potentially affected devices and implement patches as soon as possible.

It says kernel 3.8 and later is vulnerable, and we’re at 3.10.

Security Notices


Live chat
Online